Vulnerabilities > Hybridauth Social Login Project

DATE CVE VULNERABILITY TITLE RISK
2015-08-18 CVE-2015-5511 Permissions, Privileges, and Access Controls vulnerability in Hybridauth Social Login Project Hybridauth Social Login
The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social login.
network
low complexity
hybridauth-social-login-project CWE-264
5.0
2015-06-15 CVE-2015-4395 Information Exposure vulnerability in Hybridauth Social Login Project Hybridauth Social Login
The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal stores passwords in plaintext when the "Ask user for a password when registering" option is enabled, which allows remote authenticated users with certain permissions to obtain sensitive information by leveraging access to the database.
3.5